Security Vulnerability in Apple Products Affects iOS, macOS, tvOS and watchOS
CVE-2018-4086
5.9MEDIUM
Summary
A vulnerability has been discovered in several Apple operating systems, where remote attackers can exploit the issue to spoof certificate validation processes. This vulnerability is present in iOS versions prior to 11.2.5, macOS versions before 10.13.3, tvOS versions below 11.2.5, and watchOS versions earlier than 4.2.2. Attackers can leverage crafted name constraints to manipulate the security component, potentially allowing unauthorized access or data interception.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved